Why It's a Liability and How to Lead Through It
.jpg)
A client recently asked meto audit their performance review process. Pulling recent reviews is standard procedure. One of them recommended putting an employee on a performance improvement plan (PIP), noting the employee had already failed to correct course after a specific meeting.
I asked to see the documentation from that meeting. There wasn't any. When the client asked the manager directly, he came clean: he’d uploaded the employee's personnel file tohis personal ChatGPT account, answered a few prompts, and submitted the output word-for-word. The tool recommended the PIP. The tool cited the meeting.
But the meeting never happened.
Last time I wrote here, I said that after enough clients, you stop seeing thirty unrelated problems and start seeing the same handful on repeat. This is one of them. Companies ask how to start using AI for reviews and screening, but they rarely check if they already are. Most don't know their managers are using personal accounts, taking whatever a chatbot hands them without verification.
The whole AI-in-HR conversation rests on a comfortable fiction that adoption is a decision leadership hasn't made yet. It feels safe to assume you’ll evaluate vendors and roll out tools on your own timeline. That story keeps you in charge.
It's also not realistic. AI came in through the side door long ago via personal accounts and existing tools. It’s been making calls about your people ever since.
The fake meeting isn't even the biggest risk. By putting a personnel file into a consumer chatbot, the manager moved sensitive data outside the company's control. That data now lives in a system without enterprise-grade protections. In a growing number of states, if the employee wasn’t properly notified, that action violates state law.
Another client saw applicants drop from hundreds to a handful for months. The culprit? An AI vendor screening candidates. It was rejecting qualified people for lacking specific keywords or degrees from the "right" schools. Hiring managers simply accepted the tool's output, never looking closer or adjusting the filters.
One tool was invisible because a manager stayed silent. The other was invisible because everyone assumed someone else was watching it. Different tools, same blindness.
These companies weren't hiding anything. They didn't know what they didn't know. Most HR problems are visible to those inside. This one, nobody sees at all.
This is where I'm supposed to tell you regulators will catch what you miss. They won't.
Companies often bet that employment rules won't be enforced against them. For small companies, the bet frequently pays out, not because they’re right on the law, but because nobody’s checking.
The AI bet looks even safer. There’s no federal AI-in-employment law, and agencies have walked away from enforcement guidance. If you're waiting for Washington to put guardrails in place, you’ll be waiting along time.
But the bet can still fail. Employees know their rights, and states are passing their own patch work rules. When a tool fails, the liability lands on you, not just the vendor. You can sue the vendor later, but that doesn’t stop the initial damage.
I know the counter-argument: everyone else is using it, and we can’t afford to miss out. But an employment decision belongs to the employer, regardless of the tool that recommended it.
The choice isn't between using AI and not using it. It's between paying for the proactive work now or the reactive fallout later.
Some clients decide a theoretical lawsuit is cheaper than my invoice. But the math is simple. Proactive is cheaper than reactive, every time, by a massive margin. Reactive costs are unpredictable and often catastrophic.
Money isn't the only cost.If your tools treat people like they don’t matter, word gets around. Your reputation and retention suffer long before anyone files a lawsuit.
I’m not anti-AI. I’m anti-ostrich. Get your head out of the sand. Know where the risk lives and protect your people while the choice is still yours.
There are three things I tell every leader who discovers AI is already in the building.
Don't punish your way out. The reflex is to write someone up. Resist it. Disciplining people without a clear AI policy is unfair and counterproductive. You can't punish people into being transparent. Focus on honest conversations about risk instead. Reprimands can wait until the lines are drawn. You only get one chance to get this right the first time.
Map the current usage. Be honest that you're looking. Your managers are likely ahead of you. Give them the space to admit what they're using without fear of retaliation. This creates an accurate map of your actual risk and clarifies your next steps.
Bring it inside. Move AI use into an enterprise system you control. That’s the difference between a tool the company stands behind and a personnel file sitting in a private chat history. But remember, a sanctioned tool only buys you control, not a pass on oversight. You still have to watch what the tool actually does.
I keep coming back to that meeting, the one that never happened. It became part of a permanent personnel record because nobody read the AI output. If one auditor hadn't asked one question, that fiction would be waiting for a plaintiff’s attorney to find in discovery.
The goal isn't keeping AI out. That ship sailed. The job is knowing what AI is doing in your name before someone else tells you. The leaders who succeed will be those who bring AI into the open to protect their people and their culture.
Bryan Driscoll is anon-practicing lawyer, fractional CHRO, and HR consultant based in Las Vegas. He's the HR leader your employment lawyer wishes you had, someone who approaches people strategy through the lens of legal risk and compliance without losing sight of what's actually best for the workforce. He serves on the boards of the Freelancers Union and the International Human Rights ArtMovement, and his writing has appeared in Forbes, Best Lawyers, The NevadaIndependent, Nevada Current, and Lattice.